Trust Centre

Everything you need for institutional diligence.

Security, compliance and regulatory information in one place — presented honestly, with verified credentials and transparent status on what is in progress.

Security & controls

Built like critical infrastructure

Defense in depth, least-privilege access and full auditability, with embedded risk screening on every transaction.

Perimeter · WAFEncryption at rest & in transit
Secure payment infrastructureInfrastructure & monitoring
Current status

Credentials & certifications

We publish only what is verified and mark what is in progress.

Verified

FINTRAC MSB

FLOWA PAY INC., Canada. Reg. no. C100000902.

In progress

PCI DSS

Attestation targeted pre-launch.

In progress

SOC 2 · ISO 27001

Independent audit planned.

Aligned

GDPR

Privacy-by-design data handling.

Due diligence

The questions institutions ask first

Answered here rather than after three rounds of email. Where something is in progress we say so, and where a question is answered by a published policy we link straight to it.

What is your regulatory status?

FLOWA PAY INC. is registered with FINTRAC as a money services business, registration C100000902, verifiable on the public registry. That is a registration, not a licence, approval or endorsement, and not a banking, e-money or acquiring licence.

Who performs the acquiring?

Licensed acquiring and payment partners, under their own authorisations. Flowa Pay provides the technology and orchestration layer, and is not the acquirer.

How is card data handled?

Captured in a Flowa Pay-controlled payment surface and exchanged for a token on hosted and embedded integrations, so card numbers do not rest in merchant systems. The card-data environment is segmented and engineered to PCI DSS; formal attestation is in progress.

What are your security controls?

Encryption in transit and at rest, role-based least-privilege access, multi-factor authentication, signed webhooks, request validation, continuous monitoring and a documented incident-response process. The security page sets each one out.

How do you handle personal data?

Privacy-by-design handling with data minimisation, defined retention and documented processing bases, set out in the Privacy Policy, GDPR and Data Protection pages.

How do you onboard merchants?

Risk-based KYC and KYB with ultimate beneficial ownership verification, sanctions, PEP and adverse-media screening, a documented decision and ongoing monitoring proportionate to risk.

What happens in an incident?

Defined severities, escalation paths, direct notification of affected account contacts, and a written post-incident review for material incidents. Continuity and recovery are covered by published policies.

Can you support our audit?

Yes. Policies are published rather than gated, and further material for an institutional review can be requested through the contact page.

What are you not claiming?

We publish no certification we do not hold, no customer names without written consent, no partner names we are not permitted to state, and no metrics we cannot evidence.

Published policies

The full compliance library

Financial crime, risk, governance, data protection and operational resilience policies are published in full and linked from one index.

Request our diligence pack

Tell us what your review needs and we will send the security overview and compliance summary.